US2010106964A1PendingUtilityA1

Authentication terminal, authentication server, and authentication system

Assignee: HITACHI LTDPriority: Aug 7, 2008Filed: Aug 6, 2009Published: Apr 29, 2010
Est. expiryAug 7, 2028(~2 yrs left)· nominal 20-yr term from priority
H04L 9/3231H04L 63/0861
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In registration, a feature array x[i] obtained by client is basis-transformed into array X[i], transformed with a transformation filter array K[i] into a template array T[i] to be registered in the client. In authentication, the feature array y[i] is basis-transformed into an array Y[i] after inversely sorting and applied to filter K by computation V[i]=Y[i]K[i]. The server obtains array e[i]=Enc (T[i]), and the client obtains e′[i]=Enc (Σ j X[j]Y[j]α −ij ) and shuffles each elements. The shuffled array e σ ′[i] is transmitted to the server and then decoded to obtain C σ ′[i] which provides determination of whether the feature arrays x and y match with each other or not.

Claims

exact text as granted — not AI-modified
1 . An authentication terminal in an authentication system in which
 the authentication terminal configured to obtain biometric information of an individual, extract features in the biometric information of the individual as a feature array including a plurality of elements which are arranged, and transform the feature array for authentication into a transformed-for-authentication feature array, and   an authentication server configured to match the transformed-for-authentication feature array received from the authentication terminal with a transformed-for-enrollment feature array, to which a feature array for identifying the individual is transformed for registration, to authenticate the individual, are communicably coupled, the authentication terminal comprising:   an authentication terminal storage configured to store a transformation filter array including a plurality of elements having random values for transforming the feature array into the transformed-for-authentication feature array and the transformed-for-registration feature array; and   a shuffled cross-correlation computing unit configured to compute a cross-correlation between the transformed-for-authentication feature array with the transformed-for-registration feature array received from the authentication server in a encrypted domain against the authentication terminal as a cross-correlation array including a plurality of elements and shuffle the elements in the cross-correlation array as the confidential status is kept to generate a shuffled cross-correlation array.   
   
   
       2 . The authentication terminal as claimed in  claim 1 , further comprising a basis transforming unit configured to perform a basis transformation of the feature array to calculate the cross-correlation array by a cyclic convolution. 
   
   
       3 . The authentication terminal as claimed in  claim 2 , wherein the basis transformation comprises a number theoretic transformation in which a predetermined finite field is defined. 
   
   
       4 . The authentication terminal as claimed in  claim 2 , wherein the basis transformation comprises a discrete Fourier transform. 
   
   
       5 . An authentication server in an authentication system in which
 the authentication terminal configured to obtain biometric information of an individual, extract features in the biometric information of the individual as a feature array including a plurality of elements which are arranged, and transform the feature array for authentication into a transformed-for-authentication feature array, and   an authentication server configured to perform matching the transformed-for-authentication feature array received from the authentication terminal with a transformed-for-registration feature array, to which a feature array for identifying the individual is transformed for registration, to authenticate the individual are communicably coupled, the authentication server comprising:   an authentication server storage configured to store the transformed-for-registration feature array, wherein the authentication terminal computes a cross-correlation between the transformed-for-authentication feature array with the transformed-for-registration received from the authentication server in a confidential status against the authentication terminal as a cross-correlation array including a plurality of elements and shuffles the elements in the cross-correlation array as the confidential status is kept to generate a shuffled cross-correlation array;   an authentication server shuffled cross-correlation computing unit configured to receive from the authentication terminal the shuffled cross-correlation array in which the elements in the cross-correlation array are shuffled as a confidential status is kept and release the confidential status of the received shuffled cross-correlation array to obtain a shuffled cross-correlation array; and   a determination unit configured to perform the matching on the basis of the obtained shuffled cross-correlation array to determine identification of the individual.   
   
   
       6 . The authentication server as claimed in  claim 5 , wherein the determination unit inverse-basis-transforms the shuffled cross-correlation array obtained by basis-transforming the feature array to allow the authentication terminal to calculate the cross-correlation array by a cyclic convolution. 
   
   
       7 . The authentication server as claimed in  claim 6 , wherein the basis transformation comprises a number theoretic transformation in which a predetermined finite field is defined. 
   
   
       8 . The authentication server as claimed in  claim 6 , wherein the basis transformation comprises a discrete Fourier transform. 
   
   
       9 . The authentication server as claimed in  claim 5 , wherein the authentication server shuffled cross-correlation computing unit reads out the transformed-for-registration feature array of the individual from the authentication server storage, encrypts the received transformed-for-registration feature array with homomorphic Encryption for confidentiality and transmit the encrypted transformed-for-registration feature array to the authentication terminal and when receiving the encrypted transformed-for-registration feature array form the authentication terminal, the authentication server shuffled cross-correlation computing unit decodes the encrypted transformed-for-registration feature array regarding the homomorphic Encryption to obtain a shuffled cross-correlation array without confidentiality. 
   
   
       10 . The authentication server as claimed in  claim 9 , wherein the homomorphic Encryption comprises Okamoto-Uchiyama encryption. 
   
   
       11 . The authentication server as claimed in  claim 9 , wherein the homomorphic Encryption comprises Paillier encryption. 
   
   
       12 . An authentication system comprising:
 an authentication terminal configured to obtain biometric information of an individual, extract features in the biometric information of the individual as a feature array including a plurality of elements which are arranged, and transform the feature array for authentication into a transformed-for-authentication feature array;   an authentication server configured to match the transformed-for-authentication feature array received from the authentication terminal with a transformed-for-registration feature array, to which a feature array for identifying the individual is transformed for registration, to authenticate the individual, the authentication terminal and the authentication server being communicably coupled, wherein the authentication terminal comprises:   an authentication terminal storage configured to store a transformation filter array including a plurality of elements having random values for transforming the feature array into the transformed-for-authentication feature array and the transformed-for-registration feature array; and   an authentication terminal shuffled cross-correlation computing unit configured to compute a cross-correlation between the transformed-for-authentication feature array with the transformed-for-registration feature array received from the authentication server in a confidential status against the authentication terminal as a cross-correlation array including a plurality of elements and shuffle the elements in the cross-correlation array as the confidential status is kept to generate a shuffled cross-correlation array, and wherein the authentication server comprises:   an authentication server storage configured to store the transformed-for-registration feature array;   an authentication server shuffled cross-correlation computing unit configured to receive the shuffled cross-correlation array from the authentication terminal and decrypt the received encrypted shuffled cross-correlation array to obtain a shuffled cross-correlation array; and   a determination unit configured to perform the matching on the basis of the obtained shuffled cross-correlation array to determine identification of the individual.

Join the waitlist — get patent alerts

Track US2010106964A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.